Installation
The fastest way to try ContextCake on macOS is the signed, notarized app. ContextCake also runs directly from versioned source. The recommended source route is a
verified source archive; shallow Git and GitHub CLI checkouts are available when
you already use source-control tooling. The engine is dependency-free: there is
no npm install step, no install scripts execute, and the resolver quickstart
fetches nothing after the source is on your machine.
If you are still evaluating whether the model fits your team, start with the demo or the docs overview and come back here when you want the local setup path.
macOS app (recommended)
Section titled “macOS app (recommended)”Download the DMG for your Mac from app-v0.10.0. Each file is signed, notarized, and listed in SHA256SUMS.
| Mac | Download | Size | SHA-256 |
|---|---|---|---|
| Apple silicon | ContextCake-0.10.0-arm64.dmg | 118.6 MB | 4b03027833d336b8f3ea7cb69a3441ea2d4b1d173daa0a3f47fa42d83ae76d41 |
| Intel | ContextCake-0.10.0-x64.dmg | 122.0 MB | 9c49d13e9a7432049bc5e04f723e653ef508cd541dfa5416ec7c2f273e78972d |
Open the DMG and drag ContextCake to Applications. Open it from Applications; macOS may ask you to confirm the first launch.
The app’s activation path is:
- Choose Get started, then add a Markdown folder. Repository docs,
Obsidian vaults, wiki exports, and other folders containing
.md,.mdx, or.txtfiles work without conversion. - Finish source setup. ContextCake resolves the first available concept and confirms that your cascade is live.
- Choose Connect an agent and select Claude Code, Codex, Cursor, Claude Desktop, or another MCP client. The app prepares the local MCP setup and its verification step.
- Paste the supplied first-use prompt into your client and check that the answer names its source and keeps any disagreement visible.
Source setup comes before agent connection: an agent needs at least one source to
query. The app can also install the optional contextcake command when a client
needs it.
Each release page contains the matching ZIP and checksums.
Linux app (.deb)
Section titled “Linux app (.deb)”Download the package from app-v0.10.0. It is not signed; check it against its line in SHA256SUMS.
| Linux | Download | Size | SHA-256 |
|---|---|---|---|
| Debian and Ubuntu | ContextCake-0.10.0-amd64.deb | 97.4 MB | a6299f4176c652ab1ec46442a547e129cb7ffe371cc02b18a206555e3106dc6e |
The package is for x64 Debian and Ubuntu. Install it with apt, which also installs the libraries it needs:
sudo apt install ./ContextCake-*-amd64.debOpen ContextCake from your applications menu. The setup steps match the macOS app
above. The app lives in /opt/ContextCake and keeps settings and the source
list in ~/.config/contextcake (or $XDG_CONFIG_HOME/contextcake), the folder
the command-line tool reads. Chromium’s sandbox stays on: on Ubuntu 24.04 and
later the package installs an AppArmor profile that allows it.
- Updates: the app checks for new releases and links the download. It never
installs one. Install the new
.debthe same way. - Command-line tool: Help → Install Command Line Tool links
contextcakeinto~/.local/bin, with no sudo. If that folder is not on yourPATHyet, log out and back in, or add it to your shell profile. - Credentials: GitHub tokens are encrypted with your desktop keyring, such as GNOME Keyring or KWallet. Without one, the app keeps tokens in memory until it quits, and Settings → Connections says so.
Other distributions and architectures can use the CLI below.
Use the CLI without the app
The contextcake command runs on macOS, Linux, and WSL with Node.js 22 or newer. Windows works on a best-effort basis. Install the version that matches app-v0.10.0:
npm installs the tarball attached to the app-v0.10.0 release, with registry integrity sha512-RIGDfPVp7FkQM/YHo4Iphj60RAMruJegok0KFmI9m1tiegwCYsMgoBNJ13qbs5BPdpcpWUtkZB+gzwOvvKlkLg==. The package runs no install scripts.
Create a manifest, then add a folder of Markdown files as your first source:
contextcake initcontextcake source add notes --path ~/Documents/notesinit leaves an existing manifest alone. On macOS the CLI and the app read the same manifest. In WSL, the CLI keeps its own manifest in ~/.config/contextcake. It does not share a manifest with an app installed on Windows.
Connect an AI tool with the absolute path of the install you just made. Check which contextcake your shell finds. The connect command saves that full path.
command -v contextcakeclaude mcp add --scope user contextcake -- "$(command -v contextcake)" mcpcodex mcp add contextcake -- "$(command -v contextcake)" mcpTo try a command without installing, run npx --yes [email protected] init. Keep npx out of AI tool settings: it runs from a cache folder that can change.
Prerequisites for the source route
Section titled “Prerequisites for the source route”- Node.js ≥ 22
- One download route: a browser,
curl, GitHub CLI, or Git
Choose a route
Section titled “Choose a route”Every route below targets the verified app-v0.9.1 coordinated release tag. Use the archive
when you want the smallest inspectable download, or a shallow Git checkout when
you already work with source-control tools.
Terminal download (recommended)
Section titled “Terminal download (recommended)”On macOS, Linux, or WSL:
curl --fail --location https://github.com/ContextCake/context-cake/archive/refs/tags/app-v0.9.1.tar.gz \\ --output context-cake-app-v0.9.1.tar.gzYou can also download the same archive in your browser.
GitHub CLI
Section titled “GitHub CLI”If you already use gh, create a shallow checkout at the same tag:
gh repo clone ContextCake/context-cake contextcake -- \\ --branch app-v0.9.1 --depth 1cd contextcakegit clone --branch app-v0.9.1 --depth 1 \\ https://github.com/ContextCake/context-cake.git contextcakecd contextcakeGit and GitHub CLI users can skip directly to Verify the resolver.
Verify and unpack the archive
Section titled “Verify and unpack the archive”If you downloaded the archive with curl or your browser, verify it before unpacking:
printf '%s %s\n' 'f5538d20ed5cb5d0503e6624f0f3b94805524526634cc4b22e23b44bcc252201' 'context-cake-app-v0.9.1.tar.gz' | shasum -a 256 --check &&mkdir contextcake &&tar -xzf context-cake-app-v0.9.1.tar.gz -C contextcake --strip-components=1 &&cd contextcakeThese commands target the app-v0.9.1 release instead of following the
latest source checkout, and stop before extraction if the downloaded bytes do not
match the published SHA-256.
Verify the resolver
Section titled “Verify the resolver”Resolve a concept from the bundled three-layer demo, where the layers deliberately disagree:
node resolver.mjs --manifest apps/playground/manifest.json --concept decisions/primary-dbThe JSON output shows the effective merge: contributors lists each layer with its
last-updated date, every section carries the sourceLayer that won it, and sections
where layers disagree carry a conflicts array with the dissenting layers’ content
and dates, surfaced rather than hidden.
To run the full test suite (requires bash):
npm testWhat you just installed
Section titled “What you just installed”| Piece | Run with |
|---|---|
| Cascade resolver (CLI) | node resolver.mjs --manifest <manifest> --concept <id> |
| MCP server for agents | node mcp-server.mjs --manifest <manifest> |
| Interactive playground | npm run playground → http://127.0.0.1:8790 |
| Capture write path | node ingest.mjs / node write.mjs |
Source checkout
Section titled “Source checkout”Use a git checkout when you want to inspect history, contribute changes, or pin your own fork:
git clone https://github.com/ContextCake/context-cake.gitcd context-cakenode resolver.mjs --manifest apps/playground/manifest.json --concept decisions/primary-dbThe versioned archive and the current source tree both use
apps/playground/manifest.json for the bundled demo.
Why a source archive?
Section titled “Why a source archive?”Package registries have repeatedly shipped compromised AI/agent tooling through
hijacked maintainer accounts and postinstall payloads. A knowledge engine your
agents read from should have a supply chain you can audit: a source archive is
small, inspectable, and runnable as plain Node.js.
The npm package keeps to the same rules. It is the tarball attached to the signed GitHub release, published from GitHub Actions through npm trusted publishing with provenance. It has no dependencies and no install scripts. Use it when you want the CLI without the app. Use the source archive when you want to read every file before you run anything.
The signed macOS app is the recommended guided route. When the current release
includes the verified Claude Desktop .mcpb bundle, the Install page
shows its checksum-pinned download and manifest setup. A Homebrew cask will
appear only after the first-party tap has been published and tested.
Windows users can run the npm CLI or the source route in WSL. Native Windows works on a best-effort basis.
- Your first cascade: build your own layers
- Connect an agent (MCP): wire it into your AI client
- The trust boundary: read this before pointing a manifest at sources you didn’t write